Описание
Security update for openexr
This update for openexr fixes the following issues:
- CVE-2026-59183: unmapped memory access leading to crash due to
int32_tmultiplication overflow inunpack_sample_table()when decoding a crafted deep tiled EXR file (bsc#1276428). - CVE-2026-59184: out-of-bounds or use-after-free writes when processing a crafted EXR with a nonzero
dataWindow.min(bsc#1276849). - CVE-2026-59186: heap out-of-bounds write on 32-bit/ILP32 builds when a crafted tiled EXR is read through the public
TiledRgbaInputFileRGBA API (bsc#1276850). - CVE-2026-59189: heap out-of-bounds read when processing a deep image that has a non-zero
dataWindoworigin (bsc#1276855). - CVE-2026-59981: heap out-of-bounds read when procesing a deep image that has a non-zero
dataWindoworigin (bsc#1276862). - CVE-2026-59982: out-of-bounds pointer access when processing a crafted deep EXR that has a non-zero
dataWindoworigin (bsc#1276853). - CVE-2026-59983: out-of-bounds read in ILP32 builds when processing a crafted uncompressed deep-tile EXR (bsc#1276856).
- CVE-2026-59984: out-of-bounds write in ILP32 builds when processing a crafted B44-compressed scanline EXR (bsc#1276857).
- CVE-2026-59985: out-of-bounds read in ILP32 builds when processing a crafted RLE-compressed EXR (bsc#1276858).
- CVE-2026-61555: undefined behavior when processing a crafted EXR with an empty
multiViewheader attribute (bsc#1276859). - CVE-2026-68515: heap out-of-bounds write in
exrmultiviewwhen combining two specially crafted, individually valid scanline EXR files whose uniondataWindowis not aligned to one view's channel subsampling (bsc#1276848).
Список пакетов
openSUSE Leap 16.0
Ссылки
- SUSE Security Ratings
- SUSE Bug 1276428
- SUSE Bug 1276848
- SUSE Bug 1276849
- SUSE Bug 1276850
- SUSE Bug 1276853
- SUSE Bug 1276855
- SUSE Bug 1276856
- SUSE Bug 1276857
- SUSE Bug 1276858
- SUSE Bug 1276859
- SUSE Bug 1276862
- SUSE CVE CVE-2026-59183 page
- SUSE CVE CVE-2026-59184 page
- SUSE CVE CVE-2026-59186 page
- SUSE CVE CVE-2026-59189 page
- SUSE CVE CVE-2026-59981 page
- SUSE CVE CVE-2026-59982 page
- SUSE CVE CVE-2026-59983 page
- SUSE CVE CVE-2026-59984 page
Описание
OpenEXR is the reference implementation and specification for the EXR image format, widely used in the motion picture industry. In versions 3.1.0 through 3.2.10, 3.3.0 through 3.3.12, and 3.4.0 through 3.4.13, an int32_t multiplication in OpenEXRCore's unpack_sample_table() can overflow while decoding a crafted deep tiled EXR file, producing an invalid pointer that leads to a read from an unmapped memory address and a crash. Because the overflow occurs in the standard decoding path (exr_decoding_run), any application that decodes deep tiled EXR files is affected. This issue is fixed in versions 3.2.11, 3.3.13, and 3.4.14.
Затронутые продукты
Ссылки
- CVE-2026-59183
- SUSE Bug 1276428
Описание
OpenEXR is the reference implementation and specification for the EXR image format, widely used in the motion picture industry. Versions before 3.2.11, 3.3.0 through 3.3.12, and 3.4.0 through 3.4.13 allow a crafted EXR with a nonzero dataWindow.min to make TypedFlatImageChannel::row() return an invalid heap pointer, causing out-of-bounds or use-after-free writes. This occurs when an application writes rows through FlatHalfChannel::row(). Affected consumers are tools, converters, render pipeline components, or image-processing services that accept untrusted EXR files and use FlatHalfChannel::row() on loaded images. This issue is fixed in versions 3.2.11, 3.3.13, and 3.4.14.
Затронутые продукты
Ссылки
- CVE-2026-59184
- SUSE Bug 1276849
Описание
OpenEXR is the reference implementation and specification for the EXR image format, widely used in the motion picture industry. In versions before 3.2.11, 3.3.0 through 3.3.12, and 3.4.0 through 3.4.13, a crafted tiled EXR can trigger a heap out-of-bounds write on 32-bit/ILP32 builds when read through the public TiledRgbaInputFile RGBA API. The file uses a small 40x40 dataWindow but a 65537x65537 tile size. On ILP32, the Array2D<Rgba> tile-conversion buffer size calculation overflows, allocates a much smaller heap buffer, and tile decode writes past that allocation. This issue is fixed in versions 3.2.11, 3.3.13, and 3.4.14.
Затронутые продукты
Ссылки
- CVE-2026-59186
- SUSE Bug 1276850
Описание
OpenEXR is the reference implementation and specification for the EXR image format, widely used in the motion picture industry. In OpenEXRUtil versions 3.3.0 through 3.3.12 and 3.4.0 through 3.4.12, the documented TypedDeepImageChannel<T>::row() API can return an out-of-bounds pointer when a deep image has a non-zero dataWindow origin, resulting in a heap out-of-bounds read and crash, with potential information disclosure under a controlled heap layout. The flaw arises because ImfDeepImageChannel uses two conflicting coordinate models: at(x, y) uses absolute coordinates (with _base offset by dataWindow.min), while row(r) is documented as 0-based logical access. For a non-zero dataWindow.min, row(0) therefore points outside the _sampleListPointers allocation instead of at the first logical row. This issue is fixed in versions 3.3.13 and 3.4.13.
Затронутые продукты
Ссылки
- CVE-2026-59189
- SUSE Bug 1276855
Описание
OpenEXR is the reference implementation and specification for the EXR image file format, widely used in the motion picture industry. In versions through 3.2.10, 3.3.0 through 3.3.12, and 3.4.0 through 3.4.13, the OpenEXRUtil library returns an out-of-bounds pointer from the SampleCountChannel::row() API when a deep image has a non-zero dataWindow origin. The row() accessor is documented as 0-based and computes its address from an internal base that is offset for absolute pixel coordinates, so the two coordinate models conflict whenever dataWindow.min is non-zero. For a deep image whose data window has a large negative vertical origin, row(0) points far outside the allocated sample-count buffer. An application that opens an attacker-controlled deep EXR file and accesses sample counts through row() performs an out-of-bounds read, which can crash the process or, under a controlled heap layout, return adjacent heap memory as sample-count values. This issue is fixed in versions 3.2.11, 3.3.13, and 3.4.14.
Затронутые продукты
Ссылки
- CVE-2026-59981
- SUSE Bug 1276862
Описание
OpenEXR is the reference implementation and specification for the EXR image format, widely used in the motion picture industry. OpenEXR versions before 3.2.11, 3.3.0 through 3.3.12, and 3.4.0 through 3.4.13 can return an out-of-bounds pointer from TypedDeepImageChannel::row() when a crafted deep EXR has a nonzero dataWindow origin. This vulnerability occurs because the API combines zero-based row access with an absolute-coordinate-adjusted base pointer, allowing a crash or limited information disclosure. This issue is fixed in versions 3.2.11, 3.3.13, and 3.4.14.
Затронутые продукты
Ссылки
- CVE-2026-59982
- SUSE Bug 1276853
Описание
OpenEXR is the reference implementation and specification for the EXR image format, widely used in the motion picture industry. OpenEXR versions before 3.2.11, 3.3.0 through 3.3.12, and 3.4.0 through 3.4.13 are vulnerable on ILP32 builds to an out-of-bounds read. The vulnerability is reached when a crafted uncompressed deep-tile EXR causes the sample-count table size calculation in OpenEXRCore decoding.c to wrap before unpack_sample_table() iterates over the full attacker-controlled tile dimensions, allowing denial of service. This issue is fixed in versions 3.2.11, 3.3.13, and 3.4.14.
Затронутые продукты
Ссылки
- CVE-2026-59983
- SUSE Bug 1276856
Описание
OpenEXR is the reference implementation and specification for the EXR image format, widely used in the motion picture industry. OpenEXR versions 3.1.0 through 3.2.10, 3.3.0 through 3.3.12, and 3.4.0 through 3.4.13 are vulnerable on ILP32 builds to an out-of-bounds write. When a crafted B44-compressed scanline EXR causes the logical scratch size to truncate before allocation and uncompress_b44_impl() writes using the attacker-controlled channel width, allowing denial of service and memory corruption. This issue is fixed in versions 3.2.11, 3.3.13, and 3.4.14.
Затронутые продукты
Ссылки
- CVE-2026-59984
- SUSE Bug 1276857
Описание
OpenEXR is the reference implementation and specification for the EXR image format, widely used in the motion picture industry. OpenEXR versions 3.2.0 through 3.2.10, 3.3.0 through 3.3.12, and 3.4.0 through 3.4.13 are vulnerable on ILP32 builds to a heap out-of-bounds read. The issue occurs when a crafted RLE-compressed EXR causes the 64-bit unpacked size to truncate before allocation in OpenEXRCore decoding.c and unpack_32bit() reads beyond the resulting buffer, allowing denial of service. This issue is fixed in versions 3.2.11, 3.3.13, and 3.4.14.
Затронутые продукты
Ссылки
- CVE-2026-59985
- SUSE Bug 1276858
Описание
OpenEXR is the reference implementation and specification for the EXR image format, widely used in the motion picture industry. OpenEXR versions before 3.2.11, 3.3.0 through 3.3.12, and 3.4.0 through 3.4.13 are vulnerable to crashing. This occurs when Imf::GetChannelsInMultiPartFile() processes a crafted EXR with an empty multiView header attribute and Imf::viewFromChannelName() indexes the empty vector for a dotless channel name. This issue is fixed in versions 3.2.11, 3.3.13, and 3.4.14.
Затронутые продукты
Ссылки
- CVE-2026-61555
- SUSE Bug 1276859
Описание
OpenEXR is the reference implementation and specification for the EXR image format, widely used in the motion picture industry. In versions before 3.2.11, 3.3.0 through 3.3.12, and 3.4.0 through 3.4.13, exrmultiview can write past a heap allocation when it combines two attacker-supplied, individually valid scanline EXR files whose union dataWindow is not aligned to one view's channel subsampling. The utility allocates sampled channel storage using a truncated union_width / xSampling, then reads the sampled input through a Slice based on the misaligned union window, producing a heap out-of-bounds write. The trigger is normal public-tool processing, such as exrmultiview left A.exr right B.exr out.exr with crafted but valid inputs, so this is not solely an API or caller-precondition issue. This issue is fixed in versions 3.2.11, 3.3.13, and 3.4.14.
Затронутые продукты
Ссылки
- CVE-2026-68515
- SUSE Bug 1276848